Help: trojan and god knows what else

Discussion in 'Malware Help (A Specialist Will Reply)' started by willlock, Feb 25, 2008.

  1. willlock

    willlock Private E-2

    I was not paying attention and clicked ok to load a video codec onto my computer. I knew instantly that I had a problem and began running anti-spyware and antivirus programs to no avail. I went through the entire READ & RUN ME FIRST lineup and I am still having trouble.
    Currently their are no noticible symptoms. But when I run any anti spyware program they find adware.agent.bn, tracking cookies and various other things. I of course delete the offending thing but they are again present as soon as I run the programs again.
    Going 24 hrs infected now if anyone can help me I thank you. While I wait I will run some of the alternative scans.
     

    Attached Files:

  2. willlock

    willlock Private E-2

    Ran smitfraudfix

    here is the rapport.txt
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Ran smitfraudfix

    Welcome to Major Geeks!

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Is your copy of Spyware Doctor 5.1 a paid version or free trial? If free, uninstall it now.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O21 - SSODL: bxlrvps - {5D918471-C75E-46A1-95FA-2C96687E65A8} - C:\WINDOWS\bxlrvps.dll (file missing)
    O21 - SSODL: alofkmn - {047EDFB4-84B3-4A58-81D9-EC1C044A643C} - C:\WINDOWS\alofkmn.dll
    O21 - SSODL: KernelSrv - {a1cec409-6d19-4a15-ad4b-6ef79a384608} - C:\WINDOWS\Installer\{a1cec409-6d19-4a15-ad4b-6ef79a384608}\KernelSrv.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\alofkmn.dll
     
    Folder::
    C:\5735d522fde0ae4176eb9c14b7eca478
     
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "bxlrvps"=-
    "alofkmn"=-
    "KernelSrv"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds